bburman's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
ffuf/ffuf
Fast web fuzzer written in Go
Gallopsled/pwntools
CTF framework and exploit development library
PowerShellMafia/PowerSploit
PowerSploit - A PowerShell Post-Exploitation Framework
ytisf/theZoo
A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
moonD4rk/HackBrowserData
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
IdentityServer/IdentityServer4
OpenID Connect and OAuth 2.0 Framework for ASP.NET Core
docker/docker-bench-security
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
juliocesarfort/public-pentesting-reports
A list of public penetration test reports published by several consulting firms and academic security groups.
RsaCtfTool/RsaCtfTool
RSA attack tool (mainly for ctf) - retrieve private key from weak public key and/or uncipher data
EdOverflow/can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
mbechler/marshalsec
pwntester/ysoserial.net
Deserialization payload generator for a variety of .NET formatters
codingo/NoSQLMap
Automated NoSQL database enumeration and web application exploitation tool.
niklasb/libc-database
Build a database of libc offsets to simplify exploitation
anchore/anchore-engine
A service that analyzes docker images and scans for vulnerabilities
mandatoryprogrammer/xsshunter
The XSS Hunter service - a portable version of XSSHunter.com
gwen001/github-search
A collection of tools to perform searches on GitHub.
corkami/mitra
A generator of weird files (binary polyglots, near polyglots, polymocks...)
hmaverickadams/TCM-Security-Sample-Pentest-Report
Sample pentest report provided by TCM Security
mstrobel/procyon
Procyon is a suite of Java metaprogramming tools, including a rich reflection API, a LINQ-inspired expression tree API for runtime code generation, and a Java decompiler.
jhaddix/domain
Setup script for Regon-ng
gwen001/github-subdomains
Find subdomains on GitHub.
BishopFox/GadgetProbe
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths.
trek10inc/awsume
A utility for easily assuming AWS IAM roles from the command line.
BloodHoundAD/SharpHound2
The Old BloodHound C# Ingestor (Deprecated)
evets007/OSCP-Prep-cheatsheet
reconness/reconness
ReconNess is a platform to allow continuous recon (CR) where you can set up a pipeline of #recon tools (Agents) and trigger it base on schedule or events.
radii/msieve
msieve - Number Field Sieve implementation by Jason Papadopoulos
tristanlatr/wpscan_out_parse
Python parser for WPScan output files (JSON and CLI). It analyze vulnerabilities, miscellaneous alerts and warnings and other findings.